Ying Liu 0018

dblp:91/112-18 · DBLP profile ↗
← Back
14ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0001-9018-7013ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 A Collaborative Programmable LFA Defense Using Temporal Graph Learning in AIoT
abstract
In the current era of rapid advancements in Artificial Intelligence of Things (AIoT), with the increase in cloud data center operations and the limited security computing capabilities of AIoT terminal devices, link flooding attack (LFA) has emerged as a complex and stealthy new threat. However, the existing defense methods based on programmable networks usually have issues of slow offline inference and delayed defense activation. To address these issues, we propose a collaborative programmable defense framework (CPDTG) to predict, detect, and mitigate LFA. First, an early attack intention prediction model based on temporal graph learning (TGL) is proposed to accurately locate attacks and promptly activate defenses to save resource consumption during idle time. Second, a switch-native clustering algorithm independent of the global perspective is introduced for line-speed detection of LFA. The unsupervised algorithm does not rely on labeled datasets for training, which enhances its robustness against differentiated attack scenarios. Third, we propose a distributed defense mechanism that achieves the pushback deployment of adaptive rate-limiting strategies. Compressing the potential attack vector space effectively increases the difficulty of launching rolling attacks. Extensive experimental validation demonstrates the effectiveness of the proposed CPDTG in predicting and defending against LFA.
Ying Liu 0018, Yu Xia 0031, Weiting Zhang, Wei Quan 0001, Jiawen Kang 0001, Hongke Zhang
IEEE Internet Things J.2
2025 Learning-Based Proactive and Adaptive Link Flooding Attack Mitigation in AIoT
abstract
Artificial intelligence of things (AIoT) is a new networking paradigm incorporating AI and IoT, empowering multiple industries. Due to the high value of AI infrastructure in AIoT, its security issues are becoming increasingly prominent. A new type of covert DDoS attack, link flooding attack (LFA), is emerging as a vital threat. It congests critical links to AI infrastructure by manipulating multiple heterogeneous terminals to send legitimate low-speed traffic to cut off the connection of AI infrastructure while hiding itself. To quickly mitigate the LFA-induced congestion, this paper presents a learning-based proactive and adaptive LFA mitigation mechanism in AIoT. Specifically, a link suspicious level evaluation scheme based on graph autoencoder is first proposed. The potential risk links are identified by mining the link traffic features in the attack preparation and synthesizing two types of reconstruction errors, which is helpful for early to support rapid response to subsequent attacks. Second, a local traffic engineering model is presented based on maximizing the benefit of defenders. To solve the model to obtain the mitigation strategy, a solution based on deep reinforcement learning is designed to make real-time optimal local traffic path assignment decisions. Simulation results demonstrate that the proposed scheme can quickly perceive LFA and effectively resist the link congestion caused by LFA.
Yu Xia 0031, Weiting Zhang, Ying Liu 0018, Jiawen Kang 0001, Hongke Zhang
IEEE Internet Things J.3
2024 Mitigating Link-flooding Attacks in Intelligent Transportation System
abstract
Vehicular Ad hoc Network (VANET) is an important component of intelligent transportation systems. In VANET, nodes' high mobility and limited computing resources make it easy for them to be controlled by attackers to become botnets. Link flooding attack (LFA) is a new attack type that uses botnets to send legitimate low-speed traffic to flood critical links to cut off the target area, which poses new security risks for VANET. Therefore, the paper proposes an LFA mitigation scheme based on the programmable network architecture to improve security in VANETs. First, through the designed telemetry and early warning methods, the fine-grained network state can be efficiently obtained in real-time, and the link condition can be evaluated quickly. Afterward, the reroute scheduling policy for traffic is customized with the help of graph neural networks to reduce the pressure on critical links in time. The experiment shows that the scheme can rapidly mitigate LFA.
Yu Xia 0031, Ying Liu 0018, Jianhui Yin, Chengxiao Yu
VTC Spring2
2024 Multi-domain collaborative two-level DDoS detection via hybrid deep learning
Huifen Feng, Weiting Zhang, Ying Liu 0018, Chuan Zhang 0003, Chenhao Ying 0001, Zhenzhen Jiao
Comput. Networks3
2024 FedSAP: Secure Federated Learning in SDN-IoT via DRL-Enabled Social Attribute Perception
abstract
Federated learning (FL) is an innovative distributed privacy-preserving machine learning paradigm, which enables participants to collaboratively train artificial intelligence (AI) models without disclosing private data. Nevertheless, malicious participants have the potential to introduce vicious models via poisoning attacks, which jeopardizes the convergence and accuracy of the global model in FL. In this article, we propose a secure FL distributed architecture based on deep deterministic policy gradient (DDPG), which advances the accuracy of the global model and enhances system robustness. Specifically, we model the accuracy optimization problem with the goal of minimizing the overall loss function of participating devices during each FL iteration. Furthermore, we design the device nodes selection mechanism, named FedSAP, which leverages social attribute perception. Particularly, we first construct the device node selection problem as a Markov decision process (MDP), and then apply social attribute perception and attribute information to the state space ensuring the reliability of the device. Moreover, the long short term memory (LSTM) algorithm is introduced into the actor-critic network structure to learn part of the hidden state through memory inference. The extensive experimental results show that FedSAP can effectively select reliable nodes and significantly improve the accuracy of the global model.
Jiushuang Wang, Ying Liu 0018, Weiting Zhang, Chenhao Ying 0001, Jiawen Kang 0001
IEEE Internet Things J.2
2023 In-Network Collaborative Link Flooding Attack Defense with Adaptive Anomaly Analysis
abstract
The rapid growth of cloud data centers has reduced the organizational cost of botnets while significantly increasing the risk of Link Flooding Attack (LFA) to network service providers. The attacker utilizes legitimate low-rate flows with non-spoofing addresses to congest the bottleneck link, which aims to disconnect the target area. To overcome certain hitches of traditional defenses, we propose an in-network collaborative link flooding attack defense scheme (ICDLFA) to implement detection and mitigation. First, an adaptive anomaly detection algorithm, namely constrained clustering inference, is proposed to detect malicious flows at line rate without pre-trained models, which improves the adaptability of the detection algorithm to different scenarios. In particular, the anomaly detection algorithm is executed independently on a programmable switch, which significantly improves the detection efficiency by escaping the global view of the controller. Second, the collaborative mitigation mechanism propagates the traffic limitation policy to the vicinity of the attack source, which alleviates the impact on legitimate flows. In addition, the distributed defense can effectively limit the flexible transformation of attack vectors and reduce the possibility of launching subsequent attacks. Simulation results demonstrate that our in-network LFA defense scheme could accurately and effectively detect and mitigate LFA, quickly adapt to attack changes, and reduce network resource overhead.
Ying Liu 0018, Weiting Zhang, Wei Quan 0001
GLOBECOM2
2023 Deep Reinforcement Learning for On-Demand Intelligent Routing in Deterministic Networks
abstract
Deterministic networks have an obligation to guarantee deterministic transmission requirements of various applications in terms of delay, packet loss, throughput, and reliability. Traditional routing mechanisms, however, do not take sufficient advantage of the abundant network resources and can only provide limited quality of service (QoS) guarantees. Therefore, we propose an on-demand intelligent routing (OdIR) framework for deterministic networks. First, built on in-band network telemetry (INT) implemented by programming protocol-independent packet processors (P4), we design a fine-grained and high-precision awareness strategy to obtain network state information in real-time. Second, we present an intelligent routing decision approach based on the improved deep deterministic policy gradient (DDPG) algorithm. Finally, we adopt the segment routing MPLS (SR-MPLS) paradigm in the data plane to forward deterministic flows according to decision paths. Simulation results show that the OdIR framework can effectively reduce link overhead, end-to-end delay, packet loss rate, and southbound communication overhead under guaranteed deterministic QoS compared with traditional routing mechanisms.
Ying Liu 0018, Jianhui Yin, Weiting Zhang, Shanghan Xie
GLOBECOM1
2023 A Smart Retransmission Mechanism for Ultra-Reliable Applications in Industrial Wireless Networks
abstract
Emerging mission-critical industrial applications pose serious challenges to the reliability of the industrial networks currently. Heterogeneous wireless terminals access the network through various industrial gateways, but the vulnerability of edge links hinders the safe operation on the site. Existing service protection methods of wireless links satisfy reliability requirements through naive redundancy mechanisms. However, these methods are difficult to ensure the long-term safety of industrial applications and consume excessive energy. Therefore, this article proposed an on-demand service protection (OSP) mechanism, which can retransmit data on time to meet reliability demands intelligently. First, a long-term reliability model and an energy consumption optimization problem are formulated. Second, we introduced a flexible module inside the industrial gateway to identify various requirements and detect crucial data loss events. Then, an intelligent agent is designed to avoid unexpected data loss, which can generate a retransmission policy according to application requirements. Finally, multiple validations on the OSP were conducted. Both numerical results and prototype experiments illustrate that the proposed solution outperforms existing candidates in terms of reliability and energy consumption.
Ying Liu 0018, Ilsun You, Fei Song 0001
IEEE Trans. Ind. Informatics2
2022 Software-defined DDoS detection with information entropy analysis and optimized deep learning
Ying Liu 0018, Ting Zhi, Ming Shen 0001
Future Gener. Comput. Syst.1
2020 A DDoS attack detection based on deep learning in software-defined Internet of things
abstract
With the popularity of Internet of Things (IoT) applications, security has become extremely important. A recent distributed denial-of-service (DDoS) attack revealed vulnerabilities that are prevalent in IoT, and many IoT devices accidentally contributed to the DDoS attack. software-defined network provides a way to securely manage IoT devices. In this paper, we first present a general framework for software-defined Internet of Things (SD-IoT). The proposed framework consists of a SD-IoT controller, SD-IoT switches integrated with an IoT gateway, and IoT devices. We then propose a deep learning detection algorithm based on time series using the proposed SD-IoT framework. Finally, experimental results show that the proposed algorithm has good performance.
Jiushuang Wang, Ying Liu 0018, Wei Su 0006, Huifen Feng
VTC Fall2
2018 An Entropy-SVM Based Interest Flooding Attack Detection Method in ICN
abstract
As an instantiation of Information-centric Networking (ICN), Named Data Networking (NDN) was proposed. Since the Interests are recorded in the PITs of the intermediate routers until they receive corresponding Data packets or exceed the expiring time, the attackers can send excessive number of spoofed Interests to occupy the PITs, which is called Interest Flooding Attack (IFA), to degrade the network performance. In this paper, we propose an IFA detection mechanism based on Support Vector Machine (SVM), which can detect the IFA effectively. In order to improve the accuracy of the attack detection, we use the information entropy of the Interest names, the usage of PIT and the satisfaction rate of the Interests as the extracted features in the SVM classifier. In addition, we evaluate the performance of our mechanism. The simulation results validate that the mechanism can accurately and effectively detect the IFA.
Ting Zhi, Ying Liu 0018, Zhiwei Yan
VTC Fall2
2018 Defending against Packet-In messages flooding attack under SDN context
Deyun Gao, Zehui Liu, Ying Liu 0018, Chuan Heng Foh, Ting Zhi, Han-Chieh Chao
Soft Comput.3
2016 An Enhanced Scheduling Mechanism for Elephant Flows in SDN-Based Data Center
abstract
Software Defined Network (SDN) is able to provide better network management and higher utilization for data center. However the centralized control of entire network may trigger large overhead and limit the scalability of control plane. In this paper, we propose an enhanced mechanism of elephant flow scheduling in SDN-based data center. The mechanism can efficiently reduce the overhead and improve the scalability of control plane by using Parametric Minimum Cross Entropy (PMCE) algorithm. We describe the proposed approach in detail, and evaluate it in OMnet++ to verity its feasibility and effectiveness. Numerical results show that the benefits of our scheme are better than previous methods and the extra delay caused by PMCE algorithm is controllable.
Zehui Liu, Deyun Gao, Ying Liu 0018, Hongke Zhang
VTC Fall3
2014 A source mobility management scheme in content-centric networking
abstract
Content-Centric Networking (CCN) attracts much attention in the ongoing research area of the future Internet. CCN treats content as the first class entity of the network and attempts at addressing challenges in content distribution scalability, mobility and security. Mobile consumers of content may be well served in CCN due to the receiver-driven paradigm. Mobile sources of content, however, face a number of intractable problems, since content names are used both for routing of Interests and content identifying. In this paper, we borrow the idea of data and control plane separation and locator/identifier separation to design a source mobility management scheme in CCN. We design the basic architecture, and describe the handoff processes for the intra-domain movement and inter-domain movement. Finally, numerical results are presented.
Jianqiang Tang, Huachun Zhou, Ying Liu 0018, Hongke Zhang, Deyun Gao
CCNC3